Senior Research Engineer, Threat Intelligence

SecurityScorecard
Austin
Workplace: HybridFull timeUSD 140,000 - 150,000 annuallyFunction: Research & Scientific (R&D)Experience: 5-8 yearsEducation: bachelorsSkills: ["Cross-functional communication","Healthy skepticism","Delivery mindset","Engineering ownership","Workflow design thinking"]

Join STRIKE, SecurityScorecard’s Threat Intelligence team, bridging research and production. Own the full path from research outputs to deployable artifacts such as detection rules, distributed feeds, scoring inputs, and alerts. Build and extend platform components across services, runtimes, ingestion, and rules engines while driving standards adoption (STIX/TAXII) and research workflow automation. Coordinate with product and engineering so intelligence lands in customer-facing product.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SecurityScorecard
SecurityScorecard
2 months ago

Senior Research Engineer, Threat Intelligence

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Join STRIKE, SecurityScorecard’s Threat Intelligence team, bridging research and production. Own the full path from research outputs to deployable artifacts such as detection rules, distributed feeds, scoring inputs, and alerts. Build and extend platform components across services, runtimes, ingestion, and rules engines while driving standards adoption (STIX/TAXII) and research workflow automation. Coordinate with product and engineering so intelligence lands in customer-facing product.
Location: Austin
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Sr. Manager level

Key Responsibilities

  • •Own the path from research output to production-ready artifacts such as detection rules, distributed feeds, scoring inputs, and customer alerts.
  • •Build and maintain STRIKE threat intelligence platform components across multiple services and runtimes, including sandbox orchestration and rules engines.
  • •Convert research into shipped detection content (YARA, Sigma, STIX patterns, behavioral indicators) and build correlation pipelines for customer-facing intelligence.
  • •Drive adoption of STIX 2.1 and TAXII 2.1, and define and govern schemas and data contracts for downstream teams.
  • •Engineer research workflows and automation (indicator enrichment, feed normalization, sandbox triage), including eval harnesses and safe unattended execution.

Pay and Benefits

Salary: USD 140,000 - 150,000 annually
Perks:EquityHealth InsurancePaid LeaveParental LeaveLearning Budget

Key Requirements

  • •5 to 8 years in a hands-on engineering role with meaningful exposure to threat intelligence, security research, or detection engineering.
  • •Experience building production systems that consume or emit threat intel data.
  • •Bachelor's or Master's in Computer Science, Cybersecurity, or a related technical field (self-taught practitioners welcomed).
  • •Production-level Python and TypeScript/Node, plus relational and cache data stores and at least one streaming or batch data platform.
  • •Working knowledge of STIX 2.1 and TAXII 2.1, MISP, and MITRE ATT&CK, along with YARA/Sigma/STIX patterning for production detection logic.
Experience:5-8 yearsThreat intelligenceSecurity researchDetection engineeringProduction systemsOSINTTelemetry
Education:Bachelor's in Computer Science, Cybersecurity, or a related technical field
Skills:Cross-functional communicationHealthy skepticismDelivery mindsetEngineering ownershipWorkflow design thinking
Languages:English
Tech Stack:PythonTypeScriptNodeAWSContainersCI/CDRelational databasesCache data storesStreamingBatch data platformSTIX 2.1TAXII 2.1MISPMITRE ATT&CKYARASigmaSTIX patterningSQLSplunkKinesis

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

SecurityScorecard
Provides a cybersecurity ratings platform that continuously assesses and monitors organizations' and third-party vendors' security posture using external data and analytics to help enterprises manage risk, prioritize remediation, and inform vendor risk decisions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Headquarters: New York, United States
Founded: 2013
WebsiteLinkedIn